CVE-2021-32942

Description

The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.

Remediation

Solution:

  • AVEVA recommends organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. Users of InTouch 2020 R2 and all prior versions are affected and should first upgrade to one of the versions listed below, then apply the corresponding security update: InTouch 2020 R2: Update to InTouch 2020 R2 P01 InTouch 2020: Update to Security Update 1216934InTouch 2017 U3 SP1 P01: Update to Security Update 1216933

Categories

6.6
CVSS
Severity: Medium
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.04%
Vendor Advisory aveva.com
Affected: AVEVA InTouch
Published at:
Updated at:

References

Link Tags
https://us-cert.cisa.gov/ics/advisories/icsa-21-159-03 us government resource third party advisory patch
https://www.aveva.com/en/support/cyber-security-updates/ patch vendor advisory

Frequently Asked Questions

What is the severity of CVE-2021-32942?
CVE-2021-32942 has been scored as a medium severity vulnerability.
How to fix CVE-2021-32942?
To fix CVE-2021-32942: AVEVA recommends organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation. Users of InTouch 2020 R2 and all prior versions are affected and should first upgrade to one of the versions listed below, then apply the corresponding security update: InTouch 2020 R2: Update to InTouch 2020 R2 P01 InTouch 2020: Update to Security Update 1216934InTouch 2017 U3 SP1 P01: Update to Security Update 1216933
Is CVE-2021-32942 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-32942 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-32942?
CVE-2021-32942 affects AVEVA InTouch.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.